PT-2025-47583 · Unknown · Phppgadmin

Published

2025-11-17

·

Updated

2025-12-18

·

CVE-2025-60798

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions phpPgAdmin versions 7.13.0 and earlier
Description phpPgAdmin versions 7.13.0 and earlier contain a SQL injection issue in the display.php file at line 396. The application directly uses user-provided input from the query parameter in the $ REQUEST array within the browseQuery function without sufficient sanitization. An authenticated attacker can manipulate queries to execute arbitrary SQL commands, potentially compromising the entire database. The vulnerable parameter is query.
Recommendations Versions prior to 7.13.0 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-14887
CVE-2025-60798
GHSA-G6XH-WRPF-V6J6

Affected Products

Phppgadmin